Commit Graph
243 Commits
Author SHA1 Message Date
liquidraver 65311f0ea9 fix(ble): resolve two Phase 3 audit findings
1. CONFIG_BT_DEVICE_NAME_GATT_WRITABLE=y removed. The default GAP
   Device Name write permission is plain BT_GATT_PERM_WRITE — no
   bonding required (Zephyr gap_svc.c:158). Any connected peer
   (bonded or not) could rename the device. Worse, a GAP write
   updates bt_get_name() but NOT prefs.node_name, so the advertised
   name wouldn't track the renamed value. Rename now flows
   exclusively through CMD_SET_ADVERT_NAME, which is NUS-protected
   (AUTHEN required) and properly propagates via
   zephcore_ble_update_name() to prefs + GATT + adv data.

2. CONFIG_BT_DIS_FW_REV_STR synced from "1.13.0" to "v1.15.1-zephyr"
   to match CompanionMesh.cpp CMD_DEVICE_QUERY's version string.
   Comment added requiring the two to stay in sync.
2026-05-20 16:00:17 +02:00
liquidraver 0ba2721b40 refactor(companion): tighten Phase 2F polish — error codes, length checks, build assert
Three small correctness/polish improvements from BLE audit Phase 2F:

1. Five handlers (CMD_APP_START, CMD_GET_CHANNEL, CMD_SET_CHANNEL,
   CMD_DEVICE_QUERY, CMD_SEND_CHANNEL_TXT_MSG) previously responded
   with ERR_UNSUPPORTED on short-frame validation failure (because
   they fell through to the dispatcher's default break, which the
   caller converts to "unknown command"). They now explicitly
   sendPacketError(ERR_ILLEGAL_ARG) — the semantically correct code
   for "known cmd, bad frame".

2. CMD_SET_TUNING_PARAMS previously returned PACKET_OK on short
   frames without applying any change. Now sends ERR_ILLEGAL_ARG so
   the phone learns the change didn't take.

3. Added static_assert that CONFIG_ZEPHCORE_BOARD_NAME fits in 40
   bytes including its null terminator, so a future too-long board
   name fails at build time instead of producing an unterminated
   wire-format response.
2026-05-20 15:54:20 +02:00
liquidraver b39483add3 fix(companion): null-terminate contact name in CMD_ADD_UPDATE_CONTACT
The wire format reserves a 32-byte name field; if the phone sends 32
non-null bytes, ContactInfo::name has no terminator. Subsequent
LOG_INF/LOG_DBG sites using %s with contact.name then read past the
field into adjacent struct bytes (type, flags, out_path_len, ...)
until the first null. No memory corruption — serializeContact uses
StrHelper::strzcpy which is length-bounded — but log output gets
garbage and a paired peer could probe a few bytes of the struct
through log capture.

Sibling handler CMD_SET_CHANNEL at :1593-1594 already does this
defensively. Match the pattern.
2026-05-20 15:40:18 +02:00
liquidraver 988b438ec3 refactor(companion): harden telemetry buffer sizing and custom-vars snprintf
Two polish items from BLE audit Phase 2B:

1. CMD_SEND_TELEMETRY_REQ self-response buffer was uint8_t rsp[96]
   with a comment claiming 70 B worst case. Actual worst case at
   POWER_MAX_CHANNELS=4 is 82 B; if the channel cap ever grew the
   buffer would silently overflow. Replaced with a sizeof-style
   expression that tracks POWER_MAX_CHANNELS, plus an 8-byte safety
   pad. No size change today (90 vs. 96) but the upper bound auto-
   tracks any future bump.

2. CMD_GET_CUSTOM_VARS used `dp += snprintf(dp, 20, ...)` which
   advances by the would-be-written length, not bytes actually
   written. Currently safe only because gps_interval is capped
   ≤86400, but if either cap drifted or a new key was added the
   length passed to writeFrame would include uninitialized stack
   bytes between the truncation point and the (over-advanced) dp.
   Now tracks rsp_end, computes remaining per snprintf, and only
   advances dp on real progress.

Both are correctness polish, not exploitable today.
2026-05-20 11:57:37 +02:00
liquidraver bd1e022e88 fix(security): close OOB read in path-decoding callers (BLE + LoRa-anon)
Both mesh::Packet::writePath and ::copyPath did a raw memcpy of the
decoded hash_count*hash_size bytes from src to dest with no bound on
src. Two call sites used phone-supplied or LoRa-anon-supplied buffers
where the path_len byte was attacker-controlled:

  - CompanionMesh CMD_SEND_CHANNEL_DATA accepted len>=4 and called
    writePath with no src bound; a paired phone could leak up to ~65
    bytes of syswq stack into the outgoing LoRa channel-data frame.

  - RepeaterMesh handleAnonRegionsReq / handleAnonOwnerReq /
    handleAnonClockReq read reply_path_len from an unauthenticated
    LoRa anon-request payload and called copyPath without any src
    bound. Any LoRa neighbor could leak repeater stack into the
    reply path.

Hardened the API: both functions now require an explicit src_len
and reject (return 0) when the decoded byte count exceeds it.
Updated all 14 call sites across Packet/Mesh/Dispatcher/BaseChatMesh/
CompanionMesh/RepeaterMesh. Trusted callers (internal MAX_PATH_SIZE
buffers) pass MAX_PATH_SIZE; untrusted callers pass real remaining
length. Added len-5 plumbing through the anon-handler signatures.

CMD_SEND_CHANNEL_DATA also gained a local len>=5 + path_bytes
sanity check for early rejection.
2026-05-20 11:52:39 +02:00
liquidraver d7e420bf2f fix(ble,usb): three bugs from BLE audit
1. USB takeover opcode mismatch
   ZephyrCompanionUSB.cpp checked payload[0] == 0x03 with a comment
   claiming CMD_APP_START, but CMD_APP_START is 0x01 (0x03 is
   CMD_SEND_CHANNEL_TXT_MSG). The USB handshake silently dropped the
   companion app's first frame on every connection; the app appeared
   broken over USB until the user happened to send a channel message.

2. CMD_SET_ADVERT_NAME didn't propagate to BLE adv data
   Name changes were persisted to prefs but the advertising payload
   and GATT device name kept the old value until reboot. Added
   zephcore_ble_update_name() and called it from the handler.

3. No advertising-health watchdog
   If bt_le_adv_start() ever failed transiently (HCI timeout,
   controller pacing), the device would silently stop advertising
   and stay undiscoverable until reboot. Added an adv_running flag
   and a 5s watchdog in the companion housekeeping handler that
   nudges adv back on if it stops outside a connection. Tracks
   Arduino nrf52's equivalent 10s watchdog.
2026-05-20 11:09:45 +02:00
liquidraver 78f0c1c840 fix(ble): don't clobber overflow frame on congestion 2026-05-20 10:49:55 +02:00
liquidraver 3ecc42dd4d add t114 noscreen builds 2026-05-20 10:30:21 +02:00
liquidraver f0c29a612f ble cleanup 2026-05-20 10:27:42 +02:00
liquidraver a9f3b8ef3b cleanup t114, add build 2026-05-19 07:00:03 +02:00
liquidraver 924130b408 Merge pull request #20 from Calvario/t114
Add T114 variants (screen and screenless)
2026-05-19 06:54:16 +02:00
liquidraver b271179cc9 activate PSRAM in capable devices to fit OTA 2026-05-18 22:31:04 +02:00
liquidraver df30c447e5 west update (following 4.4 branch backports, main is still too noisy for us) 2026-05-18 21:52:15 +02:00
Steve Calvário d65703d82b Add T114 screen and screenless 2026-05-16 22:43:36 +01:00
Steve Calvário f2cdab84c4 Merge branch 'liquidraver:master' into t114 2026-05-15 19:54:47 +01:00
Steve Calvário 6dc86cc443 Init T114 without screen 2026-05-15 19:04:14 +01:00
liquidraver 3441caf8b0 new rx busy latch v20260514.205836 2026-05-14 22:24:48 +02:00
liquidraver a6d095bc16 edit default prefs 2026-05-12 22:07:02 +02:00
liquidraver a3bfb1e4a3 fix pubic channel anomaly v2 v20260511.125830 2026-05-11 14:42:47 +02:00
liquidraver 1bb04dd968 refactor atomicwrites, add atomic contacts save to QSPI capable devices v20260511.112139 2026-05-11 13:02:55 +02:00
liquidraver e78e197dee sx1262 fixes
- calibrate_image: revert to datasheet band table.  Narrow ±2 MHz
  window had truncation bug placing 433/869 MHz operating freq
  outside their own calibration windows.  DS §9.2.1 confirms cal
  is range-validity, not point-precision
- reset_agc: K_FOREVER mutex → K_MSEC(50).  Was holding dispatcher
  thread up to ~3 s if a long TX/RX held the SPI lock.  Now bails
  with WARN log; caller retries next maintenance interval.
2026-05-11 11:26:33 +02:00
liquidraver 2ee0fffa69 sync with vanilla 2026-05-08 10:13:42 +02:00
liquidraver 6919c3511c rx_boost state is undefined at boot (minor fix)
every LBT-retried flood packet loses its priority (fixed)
witching between LBT and non-LBT mode (or any cad.mode change) could silently skip full reconfiguration and leave the radio in the wrong mode (fixed)
2026-05-08 09:50:52 +02:00
liquidraver 66f7b8508f add/fix promicro_sx1262 build 2026-05-07 22:35:30 +02:00
liquidraver 147ac462b3 fix deleting public channel could wipe all other channels on reboot 2026-05-07 21:43:48 +02:00
liquidraver 2a8cc88262 fix fast path LBT CAD mode v20260507.103840 2026-05-07 11:37:09 +02:00
liquidraver 98fcddb502 add formatter tools 2026-05-06 21:56:23 +02:00
liquidraver 65f31ced7d no permanent gps disable on repeaters v20260506.102120 2026-05-06 10:11:09 +02:00
liquidraver 43a31e190d fix CAD IRQ status clear 2026-05-06 10:07:44 +02:00
liquidraver 6bc3ba7405 disable default duty cycling + SX driver fixes 2026-05-05 21:56:00 +02:00
liquidraverandClaude Opus 4.7 5e7adfb130 normalize source-file line endings to LF
Add .gitattributes rules so .c/.h/.cpp/.hpp are always stored as LF
(prevents EOL drift from editors with autocrlf-true defaults), and
renormalize the 30 source files that had drifted to CRLF in the index.

Pure mechanical change — `git diff --ignore-cr-at-eol` is empty.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
v20260505.131914
2026-05-05 14:56:44 +02:00
liquidraver 28e12c7eef initial companion jitter lowering 2026-05-05 14:52:12 +02:00
liquidraver e8f14442bf ramp time to 800us and duty cycle to 13/3 2026-05-05 14:52:05 +02:00
liquidraver ee2990fd16 hwconfig failsafe and duty cycle 10/6->10/4 (tests showed better reception) 2026-05-05 10:46:58 +02:00
liquidraver 9a1569c511 make rx duty cycle tuning more easy 2026-05-04 15:09:26 +02:00
liquidraver 1a956aa86a remove hot path RX, re-done the math, solves nothing, eats battery v20260502.112307 2026-05-02 12:13:29 +02:00
liquidraver 9282ac8c9c stay in full RX after TX for 3 seconds
agc reset on every lora_recv_duty_cycle entry
v20260501.191026
2026-05-01 20:46:12 +02:00
liquidraver 624fc3306c tune duty cycling 2026-05-01 08:58:55 +02:00
liquidraver a81f27aea4 implement "isradioready" for early returns in rx duty cycling 2026-04-30 21:54:59 +02:00
liquidraver 7c31045bd4 fix hang near noisefloorcalibrate 2026-04-30 21:35:06 +02:00
liquidraver 961fc1ec80 sx1262 driver fixes
-Removed broken §15.3 implicit-header workaround (wrong addresses, wrong bit, wrong condition)
-Initialize data->rx_boost_enabled from config->rx_boosted (DTS) instead of hard-coded false
-Re-apply RX gain after the first SetRx in lora_recv_async to match restart_rx / recv_duty_cycle
-Re-issue CalibrateImage(operating_freq) after Calibrate(ALL) to keep image-rejection band correct on EU868 / 433 MHz / 779 MHz
-rx_cb_gen converted from uint32_t to atomic_t — atomic_set/get/inc at all 13 sites; local snapshot is now atomic_val_t
2026-04-30 21:18:50 +02:00
liquidraver 8a7dacf55d increase sx1262 power to 140mA 2026-04-30 20:52:21 +02:00
liquidraver f947b6b5b1 increase preamble like vanilla v20260430.112448 2026-04-30 12:58:33 +02:00
liquidraver 9938d0e6ca fix a race condition in sx driver 2026-04-30 12:56:42 +02:00
liquidraver e930d6cc9c more small security fixes 2026-04-30 09:53:03 +02:00
liquidraver 62232bf609 small ble fixes 2026-04-30 09:23:56 +02:00
liquidraver 0e01fb2bb0 small security fix 2026-04-29 21:01:01 +02:00
liquidraver 5dc07d78ba force unscoped send on magic scope word: "none" even if there is a default scope 2026-04-29 13:17:04 +02:00
liquidraver b84830b3b3 (greatly) improve our BLE v20260429.104549 2026-04-29 12:09:21 +02:00
liquidraver 4506280162 fix(sx126x): recover and re-arm duty-cycle RX after BUSY timeout 2026-04-29 11:11:32 +02:00